INFORMATION SECURITY POLICY
The Management of the Lyntia Group (hereinafter, the “Company”), comprising Lyntia Networks, S.A. and Global Fontibre, S.L., recognises that the security of information, networks and services is essential to the proper conduct of its activities. Any loss of confidentiality, integrity, availability, authenticity or traceability of information, as well as any interruption to services, may significantly affect the Company’s operations and compromise business continuity.
As a common framework for all the Company’s entities and activities in Spain and Portugal, the Lyntia Group adopts Directive (EU) 2022/2555 (NIS 2) as a reference framework for strengthening its cyber resilience and cybersecurity risk management.
The Company also applies the standards and regulatory frameworks applicable to it, including ISO/IEC 27001, the Spanish National Security Scheme at HIGH category and, in Portugal, the Cybersecurity Legal Framework (Regime Jurídico da Cibersegurança), approved by Decree-Law No. 125/2025, as well as ANACOM Regulation No. 303/2019 regarding the security and integrity of electronic communications networks and services.
Accordingly, the Company undertakes to establish, implement, maintain and continuously improve an Information Security Management System, with the aim of ensuring:
- • The confidentiality and protection of valuable, sensitive and personal information.
- • The integrity, accuracy and reliability of information.
- • The availability of information, networks and services in order to meet business needs.
- • The authenticity of information and of the services supported by it.
- • The traceability of relevant actions and operations carried out within the Company.
- • Compliance with all applicable legal, regulatory, contractual and standards-based requirements.
- • The protection of the rights and freedoms of data subjects.
- • The application of the principle of accountability to all personal data processing activities, from the design stage and throughout their entire life cycle until completion.
- • The updating, maintenance and availability of documentation relating to information security, data protection and business continuity.
- • Information security and data protection training and awareness for all employees.
- • The reporting to Management of high-impact security incidents, as well as their investigation and management by the relevant information security functions.
- • The management of technological and cybersecurity risks through a risk management framework enabling such risks to be treated to a level acceptable to the Company.
Requirements applicable in Portugal
For these purposes, the Company undertakes to ensure:
- • The security and integrity of electronic communications networks and services through the adoption of appropriate technical, operational and organisational measures to prevent, manage and reduce security risks, as well as to prevent or minimise the impact of incidents on users and services.
- • The approval and supervision, by the governing body, of cybersecurity risk management measures, together with the regular provision of training in this area.
- • The notification of security incidents or losses of integrity having a significant impact to the competent authorities, in accordance with the circumstances, time limits, channels and formats established by law.
In order to give effect to these commitments, the Company has developed this Information Security Policy, together with the policies, standards and procedures implementing it.
Management establishes the security objectives required to promote the continuous improvement of the Information Security Management System, in the belief that this will contribute to improving the processes and services offered to its customers, while respecting their legally established rights.
Management formally commits to allocating the necessary and sufficient resources for the proper development, maintenance and improvement of the provisions set out in this Policy.
This Policy shall be available on the corporate website. The internal policies, standards and procedures implementing it shall be made available to the intended recipients through the established internal channels and shall be updated whenever necessary.
This Policy shall be published and communicated to all persons providing services to the Company and, where appropriate, to the competent authorities, in accordance with the terms laid down by the applicable regulations. It shall be reviewed at least annually and whenever relevant changes, significant security incidents or regulatory amendments affecting its content occur.
The Information Security Policy approved by the Company’s Joint Administrator shall apply from the day following its publication.
This Information Security Policy was approved by the Company’s CEO and shall apply from the day following its publication on the corporate website.